Note: The examples on this page are drawn from published public reports, regulatory guidance, and reputable news sources. They are presented to illustrate common themes in risk management failures—not to allege current failings at any organisation beyond what has been publicly documented.

Why This Matters

Academy trusts operate in a demanding regulatory environment. The Academies Trust Handbook sets clear expectations for governance, internal control, and risk management. When these systems fail, the consequences can be severe—for pupils, staff, and the trust's reputation.

Understanding where things have gone wrong elsewhere helps trustees and executives recognise vulnerabilities in their own arrangements.

🛡️ Safeguarding and Compliance Drift

Safeguarding failures remain one of the most serious risk categories for schools. Published ESFA (formerly EFA) investigation reports have repeatedly identified patterns where compliance controls deteriorated over time without adequate board oversight.

The Cuckoo Hall Academies Trust investigation (published 2016) identified significant failings including: incomplete Single Central Record (SCR) checks, inadequate DBS verification processes, fire safety compliance gaps, and insufficient risk assessment procedures. Critically, the investigation found that these risks had not been adequately escalated to trustees, and risk registers were not being maintained as live documents.

The trust was subsequently rebrokered, with schools transferred to new sponsors.

How EduRisk helps

  • Live risk register with safeguarding as a core category—ensuring SCR, DBS, and fire safety risks are tracked centrally
  • Assigned owners and review dates with automated reminders prevent compliance drift
  • Board summary reports ensure trustees have visibility of escalating or unresolved risks
  • Full audit trail demonstrates due diligence to regulators and auditors

🏗️ Estates and Building Safety: The RAAC Crisis

In August 2023, the Department for Education issued urgent guidance requiring schools to identify and mitigate risks from Reinforced Autoclaved Aerated Concrete (RAAC). This lightweight concrete, used widely in school buildings from the 1950s to 1990s, had been found to pose structural risks including sudden collapse.

The resulting disruption affected over 200 schools and colleges at its peak, with some institutions requiring partial or full closures, emergency decanting of pupils, and significant business continuity challenges. Analysis from the Education Policy Institute highlighted that many trusts had limited visibility of their estates risk profile, with condition surveys incomplete or outdated.

Key lessons included: the need for systematic estates risk identification, integration of building condition data into board-level risk registers, and robust business continuity planning for premises-related disruption.

How EduRisk helps

  • Dedicated estates/premises risk category ensures building condition risks are captured alongside other organisational risks
  • Trust-wide visibility allows central teams to identify which schools face similar estates risks
  • Mitigating actions and residual risk scoring help boards understand whether controls are adequate
  • Links to business continuity planning ensure estates risks connect to operational resilience

đź“‹ Governance After a Major Incident

When a significant incident occurs—such as a school fire—the aftermath often reveals weaknesses in risk management, insurance arrangements, and board oversight that had previously gone unnoticed.

The Vantage CE Academies Trust received a Financial Notice to Improve (FNtI) following a school fire in 2019. The subsequent ESFA investigation identified that the trust had inadequate insurance arrangements, with cover insufficient for the actual reinstatement costs. The investigation also found breaches of the Academies Trust Handbook relating to financial management, internal control, and governance oversight of residual risk.

This case illustrates how risks that appear theoretical can crystallise rapidly, and how gaps in board-level risk oversight only become apparent when incidents occur.

Source: ESFA Financial Notices to Improve register (GOV.UK). Vantage CE Academies Trust FNtI published 2020.

How EduRisk helps

  • Insurance and business continuity risks captured in the central register with clear ownership
  • Residual risk scoring forces consideration of whether mitigations (including insurance) are truly adequate
  • Audit trail supports Notice to Improve readiness—demonstrating what was known, when, and what actions were taken
  • Board reports highlight high residual risks requiring trustee attention

đź’» Cyber Security and Operational Disruption

Ransomware and cyber attacks on UK schools and trusts have increased significantly in recent years. The National Cyber Security Centre (NCSC) and Department for Education have issued specific guidance for the education sector, recognising schools as attractive targets due to the sensitive data they hold and often limited IT resources.

While many incidents go unreported, several high-profile cases have been widely covered. Large multi-academy trusts have reported recovery costs running to six figures following ransomware attacks, with disruption lasting weeks. In some cases, exam data, safeguarding records, and financial information have been compromised or encrypted.

The common theme in post-incident reviews is that cyber risk was not being treated as a board-level concern. Risk registers either omitted cyber entirely, or recorded it without clear ownership, controls, or residual risk assessment. When attacks occurred, there was no documented business continuity plan for IT systems failure.

How EduRisk helps

  • Cyber/IT security included as a standard risk category, prompting trusts to assess and document these risks
  • Clear ownership ensures someone is accountable for cyber risk controls and review
  • Mitigating actions link to IT policies, backup procedures, and incident response plans
  • Board reports bring cyber risk to trustee attention alongside other strategic risks
  • Our own security practices follow NCSC guidance and industry standards

📊 Why Spreadsheet-Based Risk Registers Fail

Many trusts still manage risk using spreadsheets shared via email or stored on network drives. While this approach may work initially, it creates systemic vulnerabilities that become apparent under scrutiny or during incidents.

Common failure patterns include:

  • Stale data: Review dates pass without action; the register becomes a static document rather than a live management tool
  • No clear ownership: Risks are logged but nobody is accountable for monitoring controls or escalating concerns
  • Version control problems: Multiple copies circulate; it's unclear which is current or authoritative
  • No audit trail: When auditors or regulators ask what was known and when, there's no evidence of the evolution of risk assessment
  • Weak board reporting: Collating data for board packs requires hours of manual work; residual risk trends are invisible
  • Siloed view: Each school maintains its own register; the trust lacks visibility of common risks or emerging patterns

These weaknesses feature repeatedly in ESFA investigation reports and audit findings. A Financial Notice to Improve often requires trusts to demonstrate improved internal control—including risk management—and spreadsheet-based systems rarely provide the evidence required.

How EduRisk helps

  • Purpose-built system with automatic reminders ensures the register stays live
  • Every risk has an assigned owner who receives notifications when reviews are due
  • Single source of truth eliminates version confusion
  • Full audit trail logs every change with timestamps and user attribution
  • Board-ready reports generated in seconds, not hours
  • Trust-wide dashboard gives central teams visibility across all schools

Summary: Risk Categories and EduRisk Features

How EduRisk addresses each category of risk management challenge

Risk Category Common Failure Pattern EduRisk Solution
Safeguarding & Compliance Drift without board visibility; static registers; no escalation Live register, owners, reminders, board summaries
Estates & Building Safety Incomplete condition data; no link to continuity planning Estates category, trust-wide view, BCP integration
Insurance & Business Continuity Gaps only visible after incidents; inadequate cover Residual risk scoring, audit trail for scrutiny
Cyber & IT Security Not treated as board-level; no ownership or controls Cyber category, clear ownership, linked controls
Governance & Internal Control Spreadsheets; no audit trail; weak board packs Automated reports, full history, FNtI readiness

Regulatory Context

Understanding the expectations placed on academy trusts

đź“–

Academies Trust Handbook

The ATH (formerly Academies Financial Handbook) sets out the requirements for governance, financial management, and internal control. It explicitly requires trusts to manage risks and have a system of internal control.

Learn more about ATH requirements →

🔍

ESFA Oversight

The Education and Skills Funding Agency monitors trust compliance. Financial Notices to Improve are issued when significant weaknesses are identified, requiring trusts to demonstrate remediation of control failures.

đź“‹

External Audit

Annual external audits assess whether trusts have adequate systems of internal control. Auditors increasingly expect to see documented risk management processes with clear evidence of board oversight.

Ready to Strengthen Your Risk Management?

EduRisk is designed specifically for UK academy trusts—helping you meet regulatory expectations while making risk management genuinely useful.

Request a Demo See All Features

Contact us at hello@edurisk.uk